if the code isn't in your index.php, I would suspect a template got changed. If your host runs setuid (where the apache process runs as the owner rather than as nobody/www-data or an unprivileged account), any remote exploit would allow them to overwrite a number of files. It would be more difficult if they didn't run setuid.
you mentioned Joomla, are you running the latest patches for that? They had 5 or 6 exploitable bugs that were patched in December.
So far, I haven't seen evidence of an issue on Wordpress 2.0.2 that we couldn't find exploited through other software running on that site.
Any method that it occurred, its in your best interest to figure out how it was exploited.... because it will happen again.. and again... and again.
__________________
SnapReplay.com a different way to share photos - iPhone & Android
|